Realtek Wi-Fi¶à¸ö°²È«·ì϶
°ä²¼¹¦·ò 2021-02-070x00 ·ì϶¸ÅÊö
Realtek RTL8195AMÊÇÒ»¿î¸ß¶È¼¯³ÉµÄµ¥Ð¾Æ¬£¬£¬£¬£¬£¬£¬£¬ÓµÓе͹¦ºÄ»úÔ죬£¬£¬£¬£¬£¬£¬¼«¶ÈÊʺÏÀûÓÃÓÚIoT£¨ÎïÁªÍø£©¡£¡£¡£¡£¡£
2021Äê02ÔÂ06ÈÕ£¬£¬£¬£¬£¬£¬£¬ÒÔÉ«ÁÐÎïÁªÍø°²È«¹«Ë¾VdooµÄ×êÑÐÈËÔ±Åû¶ÁËÔÚRealtek RTL8195A Wi-FiÄ£¿£¿£¿£¿£¿£¿£¿éÖз¢ÏÖµÄ6¸ö°²È«·ì϶£¬£¬£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÄÜÀûÓÃÕâЩ·ì϶À´»ñµÃrootÓû§µÄ½Ó¼ûȨÏÞ²¢½ÚÔìÉ豸µÄÎÞÏßͨѶ¡£¡£¡£¡£¡£Ö»¹ÜĿǰÕâЩ·ì϶Òѱ»½¨¸´£¬£¬£¬£¬£¬£¬£¬µ«Ê¹ÓÃRealtek RTL8195A Wi-FiÄ£¿£¿£¿£¿£¿£¿£¿éµÄǶÈëʽÉ豸½«Â¶³öÔÚÔ¶³Ì¹¥»÷µÄ·çÏÕÖС£¡£¡£¡£¡£
0x01 ·ì϶ÏêÇé

RTL8195A оƬ֧³ÖWEP¡¢WPAºÍWPA2Éí·ÝÑé֤ģʽ¡£¡£¡£¡£¡£×êÑÐÈËÔ±°µÊ¾£¬£¬£¬£¬£¬£¬£¬ Wi-FiÄ£¿£¿£¿£¿£¿£¿£¿éµÄWPA2ËÄ´ÎÎÕÊÖ»úÔìÔÚÈÏ֤ʱÈÝÒ×´æÔÚ²Ö¿âÒç³öºÍÔ½½ç¶ÁÈ¡ÎÊÌâ¡£¡£¡£¡£¡£
´Ë±í£¬£¬£¬£¬£¬£¬£¬Õâ´Î·¢Ïֵķì϶»¹»áÓ°ÏìÆäËüÄ£¿£¿£¿£¿£¿£¿£¿é£¬£¬£¬£¬£¬£¬£¬ÈçRTL8711AM¡¢RTL8711AFºÍRTL8710AF¡£¡£¡£¡£¡£ÆäÖÐ×îÑϳÁµÄÊÇÒ»¸ö²Ö¿âÒç¶Âí½Å£¨¸ú×ÙΪCVE-2020-9395£©£¬£¬£¬£¬£¬£¬£¬Ëü¿ÉÄܵ¼ÖÂÉ豸ºÍÄ£¿£¿£¿£¿£¿£¿£¿éµÄͨѶÆëÈ«±»½ÚÔì¡£¡£¡£¡£¡£¸Ã·ì϶ÎÞÐè֪·Wi-FiÍøÂçÃÜÂ루PSK£©Ò²¿É±»ÀûÓᣡ£¡£¡£¡£
ÔÚÎÞÐè֪·Wi-FiÍøÂçÃÜÂ루PSK£©µÄÇé¿öÏ£¬£¬£¬£¬£¬£¬£¬¹¥»÷ÕßÒ²Äܹ»Í¨¹ýÀûÓÃCVE-2020-25853ºÍCVE-2020-25857µ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£ÈôÊǹ¥»÷ÕßÖªÂ·ÍøÂçµÄPSK£¬£¬£¬£¬£¬£¬£¬ÔòÄܹ»Í¨¹ýÀûÓÃCVE-2020-25854¡¢CVE-2020-25855ºÍCVE-2020-25856Ô¶³ÌÖ´ÐдúÂë»òµ¼Ö»ؾø·þÎñ¡£¡£¡£¡£¡£
±¾´ÎÅû¶µÄ·ì϶ÈçÏ£º
²úÆ· | CVE | ÀàÐÍ | ÆÀ¼¶ | Ó°ÏìÁìÓò |
Realtek RTL8195AM¡¢RTL8711A¡¢RTL8711AFºÍRTL8710AF | CVE-2020-9395 | »ùÓÚ²Ö¿âµÄ»º³åÇøÒç³ö | ¸ßΣ | < 2.0.6 |
Realtek RTL8195A Wi-FiÄ£¿£¿£¿£¿£¿£¿£¿é | CVE-2020-25853 | Ô½½ç¶ÁÈ¡ | ÖÐΣ | < 2.0.8 |
CVE-2020-25854 | »ùÓÚ²Ö¿âµÄ»º³åÇøÒç³ö | |||
CVE-2020-25855 | ||||
CVE-2020-25856 | ||||
CVE-2020-25857 |
0x02 ´ëÖý¨Òé
ĿǰÓйطì϶Òѱ»½¨¸´£¬£¬£¬£¬£¬£¬£¬½¨ÒéÉý¼¶ÖÁ2.0.8»ò¸ü¸ß°æ±¾¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://github.com/ambiot/amb1_arduino
0x03 ²Î¿¼Á´½Ó
https://www.realtek.com/en/products/communications-network-ics/item/rtl8195am
https://securityaffairs.co/wordpress/114280/security/realtek-rtl8195a-flaws.html?
https://www.amebaiot.com/en/ameba-arduino-getting-started/
https://nvd.nist.gov/vuln/detail/CVE-2020-9395
0x04 ¹¦·òÏß
2021-02-06 Vdoo¹«¿ªÅû¶·ì϶
2021-02-07 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ